CVE-2026-83540
Received Received - Intake

Windows Login Token Reuse in wolfSSHd

Vulnerability report for CVE-2026-83540, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-07

Last updated on: 2026-10-07

Assigner: wolfSSL Inc.

Description

When password or public key authentication is used with the Windows port of wolfSSHd, the Windows logon token acquired for one authenticated connection is not released before a token is acquired for a subsequent connection, resulting in user login poisoning between connections. A less privileged user with a valid account on the server can exploit this to force a login as a more privileged user. The vulnerability was introduced with the initial Windows port of wolfSSHd in wolfSSH version 1.4.15 and affects all versions through 1.5.0. Non-Windows builds of wolfSSHd are not affected.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-07
Last Modified
2026-10-07
Generated
2026-10-07
AI Q&A
2026-10-07
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wolfSSL wolfSSH 1.4.15

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
CWE-613 According to WASC, "Insufficient Session Expiration is when a web site permits an attacker to reuse old session credentials or session IDs for authorization."

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the Windows port of wolfSSHd. When password or public key authentication is used, the Windows logon token for one connection is not released before a new token is acquired for another connection. This allows a less privileged user to exploit the issue and force a login as a more privileged user.

Detection Guidance

Detecting this vulnerability requires checking if your wolfSSHd Windows version is affected. Verify the installed version using commands like 'wolfsshd -v' or checking the binary metadata. Inspect logs for unusual login patterns where a lower-privileged user gains higher privileges. Monitor Windows Event Logs for failed and successful SSH logins, focusing on token acquisition events.

Impact Analysis

A less privileged user with a valid account on the server could exploit this to gain unauthorized access as a more privileged user. This could lead to privilege escalation, unauthorized data access, or system control depending on the server's configuration.

Mitigation Strategies

Upgrade wolfSSH to the latest version where the token handling issue is fixed. If upgrading is not possible, disable password and public key authentication on the Windows wolfSSHd server. Restrict SSH access to trusted networks and users. Monitor for unauthorized privilege escalations and review authentication logs regularly.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-83540. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart